Trust

Security

The parts of Plio that exist specifically so that the wrong person cannot read the wrong record.

Security controls

Permissions in the query

Role and team scoping is applied where records are fetched, not where they are drawn. A Manager's request returns their team's rows; a Sales user's returns their own. Editing the interface, or calling the API directly, does not widen what comes back.

Organisation isolation

Every record carries the organisation it belongs to, and every query is scoped to the caller's organisation. Users who belong to more than one org switch between them explicitly; nothing crosses.

OAuth-only mailbox access

Plio never asks for a mail password. Each user grants access through Google or Microsoft, the token is bound to that user, and they can revoke it from their provider account at any time. No shared mailbox credential exists to leak.

Audit logs

Every create, update and delete is recorded with who did it, when, and a field-by-field before and after diff. Retention follows your plan; Enterprise keeps everything.

Tab-level access control

An admin decides which roles can see which tabs at all. A role without access to the Audit log tab cannot reach it, in the UI or otherwise.

Your data, exportable

Being able to leave is a security property. CSV export on all 7 record modules and PDF export from Reports are available to you at any time, without asking us.

PLACEHOLDER. The section below states intent. Fill in the specifics you can actually evidence — hosting region, encryption in transit and at rest, backup cadence and restore testing, access controls on the production database, and any certification you hold or are pursuing. Do not claim a certification you do not have.

Infrastructure

Internal access

Reporting a vulnerability

Send it to support@pliocrm.com with enough detail to reproduce it. We will confirm receipt within two working days and keep you updated until it is closed. Please do not test against another customer's organisation, and give us a reasonable window before publishing.